CISOOnline

Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes

CVE-2026-63692 in CSM, also rated 10, similarly reports the lack of authentication controls for critical functions in the authorization proxy and tenant service. Threat actors could potentially gain “complete administrative control” over the authorization service, Dell said. The 9.9-rated CVE-2026-67269 in the CSM’s core controller system, meanwhile, could allow a low-privilege remote attacker to gain root-level access and “completely compromise all nodes” in the Kubernetes cluster.

Dell has also patched 9.8-rated CVE-2026-54472 in CSM, which could allow threat actors to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM authorization proxy; and 9.6-rated CVE-2026-6727 in CSM, which could give attackers the ability to effectively bypass Kubernetes access controls, gain cluster-wide read access, and create cluster-scoped access controls.

The 9.6-rated path traversal vulnerability CVE-2026-86360 in DSU, meanwhile, could allow threat actors to execute arbitrary code with root privileges. This would enable “complete compromise” of the vulnerable app as well as the underlying operating system, Dell said.



Source link